CVE Tools
Back to feed
News roundup npm packages SideWinder supply-chain ClickOnce npm

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

The Hacker News·By The Hacker News··21 min read
CVE Tools coverage

This week's ThreatsDay highlights include a new remote code execution vulnerability in the Odysseus AI workspace and a set of critical flaws in Samsung devices that could lead to full system compromise with a single click. The vulnerabilities (CVE-2025-21079 and CVE-2025-58486) stem from design oversights in Samsung’s Bixby virtual assistant, enabling attackers to exploit auto-granted Android permissions for privilege escalation. Meanwhile, SideWinder has adopted a new multi-stage attack chain using ClickOnce application files delivered via phishing PDFs, and an npm supply chain campaign dubbed "Flooding Dropper" has distributed over 800 malicious packages. These developments underscore the growing complexity and accessibility of cyberattacks, particularly those leveraging trusted tools and automation.